---
title: Inside Akira’s Surge – What You Need to Know
description: Learn how the Qilin ransomwareboperates using Conti-like TTPs. Explore key findings, ransom trends, and actionable mitigation strategies from experts.
---

[IronINTEL](https://www.irongatesecurity.com/ironintel)

# [Inside Akira’s Surge – What You Need to Know](https://www.irongatesecurity.com/ironintel/inside-akiras-surge-what-you-need-to-know)

 Written by [IronGate](https://www.irongatesecurity.com/ironintel/author/irongate) | Sep 16, 2025 4:50:00 PM

# **Akira Ransomware Surges Through the Targeting of VPNs **

IronGate has observed a marked rise in Akira ransomware incidents across multiple industries, echoing recent public reporting. Adversaries are actively exploiting SonicWall SSL VPN vulnerabilities, most notably CVE-2024-40766, to gain initial access. Their campaigns align with Akira’s well-documented tactics: credential compromise, double extortion, and multi-platform ransomware deployment. 

###### Threat Actor Profile: Akira Ransomware 

- **First Seen:** March 2023 
- **Type:** Ransomware-as-a-Service (RaaS) 
- **Target Platforms:** Windows, Linux, VMware ESXi 
- **Encryption Extensions:** .akira, .powerranges, .akiranew 
- **Ransom Notes:** akira\_readme.txt, powerranges.txt 
- **Extortion Model:** Double extortion (data theft + encryption) 
- **Known Affiliations:** Suspected ties to the **Conti** ransomware gang 

**Attack Lifecycle **

Initial Access 

- Exploit public-facing apps including unpatched VPNs (Cisco CVE-2023-20269, SonicWall CVE-2024-40766) 

- Valid accounts / compromised credentials 

- Spearphishing  

Persistence & Privilege Escalation 

- Domain account creation 
- Credential dumping using *Mimikatz and  LaZagne* 

Lateral Movement & Discovery 

- Network scanners (*SoftPerfect, Advanced IP Scanner*) 
- Remote access tools (*AnyDesk, RustDesk*) 

Exfiltration & Impact 

- File transfer tools (*FileZilla, WinSCP, Rclone*) 

- Shadow copy deletion 

- Data leak site for public shaming  

Observed Attack Flow 

1. Brute-force or credential stuffing against SSL VPN 
2. Privilege escalation via misconfigured LDAP groups 
3. Remote access setup (*RustDesk, AdaptixC2*) 

Recommended Mitigations 

- **Keep systems up to date**   
  Regularly apply patches and updates, especially to firewalls, VPNs, and remote access tools, to close known vulnerabilities. Immediately apply patches for CVE-2024-40766 and CVE-2023-20269. *Be sure to test the patches were applied correctly.* 

- **Use Multi-Factor Authentication (MFA)**   
  Require MFA for VPN, email, and remote logins. Favor authenticator apps or hardware tokens over SMS. 

- **Practice good password hygiene**   
  Remove inactive accounts, enforce strong passwords, rotate credentials regularly, and monitor for repeated failed login attempts. 

- **Limit attacker movement**   
  Segment networks so sensitive systems are isolated, and use Endpoint Detection & Response (EDR) tools to spot and stop unusual activity. 

- **Protect and test backups**   
  Keep multiple backups (offline, cloud, local), store them securely away from the main network, and test restoration often to ensure reliability. 

- **Conduct Regular Penetration Tests**   
  Run penetration tests at least once a year to simulate real-world attacker behavior. This helps validate whether configurations, security controls, monitoring, and detection tools are working effectively — and reveals gaps before adversaries can exploit them. 

References 

- [CISA Advisory: Akira Ransomware](https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-109a) 

- [HHS Analyst Note on Akira](https://www.hhs.gov/sites/default/files/akira-randsomware-analyst-note-feb2024.pdf) 

- [The Hacker News: SonicWall Exploitation](https://thehackernews.com/2025/09/sonicwall-ssl-vpn-flaw-and.html) 

[Contact us](https://www.irongatesecurity.com/contact) today to learn more about our [Digital Forensics and Incident Response (DFIR)](https://www.irongatesecurity.com/digital-forensics-incident-response) services.

<https://www.irongatesecurity.com/hs/cta/wi/redirect?encryptedPayload=AVxigLKM6Hn6GA4VUREVUXLSRxww7kZnA%2B1io3hnsXmyAGdpNtXMVsCxJmZTQCWH7ulkPN0NQKq6HZ7lvCflkoibvRykDL9q99%2FeHz%2BWhm%2F6b%2BeldgnUAA1iTTMSUgcDjD04QirJ0a87H6DENJB7dKG8HluC2NXHLzlv4H75J9kDI5VarDY%3D&webInteractiveContentId=129984586382&portalId=43428275>

|  | [Steve Ramey](https://www.irongatesecurity.com/steve-ramey) has spent the past two decades helping clients protect, investigate, and respond to events involving their digital interests. He has led hundreds of data breach investigations, assessed incident response and security programs, and successfully advised organizations through extortion negotiations. |
| --- | --- |

 

[View full post](https://www.irongatesecurity.com/ironintel/inside-akiras-surge-what-you-need-to-know)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "IronGate"
  },
  "dateModified" : "2025-09-17T18:49:43.997Z",
  "datePublished" : "2025-09-16T16:50:00Z",
  "headline" : "Inside Akira’s Surge – What You Need to Know",
  "image" : {
    "@type" : "ImageObject",
    "height" : 600,
    "url" : "https://43428275.fs1.hubspotusercontent-na1.net/hubfs/43428275/thumbnail_IRONGATE_CareerPosts_Miner_1200x600_v2-1.jpg",
    "width" : 1200
  },
  "mainEntityOfPage" : "https://www.irongatesecurity.com/ironintel/inside-akiras-surge-what-you-need-to-know",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60,
      "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
      "width" : 60
    },
    "name" : "IronINTEL"
  }
}
```